← Back
CWE-640

317 CVEs • Abstraction: Base • Likelihood of Exploit: High

Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

JSON object

Loading...

CVEs (317)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pilz
1Pmc
Jun 17, 2026
Dec 26, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.
1Sick
1Sim2000 Firmware
Jun 17, 2026
Dec 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the...Show more
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The recommended solution is to update the firmware to a version >= 1.13.4 as soon as possible (available in SICK Support Portal).Show less
1Ifm
2Moneo Qha200 Firmware
Moneo Qha210 Firmware
Jun 17, 2026
Dec 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.
1Backclick
1Backclick
Jun 17, 2026
Nov 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.
1Schneider Electric
36Ecostruxure Control Expert
Ecostruxure Process ExpertModicon M340 Bmxp341000 Firmware+33 more
Jun 17, 2026
Sep 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: Eco...Show more
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control Expert) (V15.0 SP1 and prior), EcoStruxure Process Expert, Including all versions of EcoStruxure Hybrid DCS (former name of EcoStruxure Process Expert) (V2021 and prior), Modicon M340 CPU (part numbers BMXP34*) (V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*) (V3.20 and prior).Show less
1Backdropcms
1Backdrop Cms
Jul 9, 2026
Aug 1, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
1Priority Software
1Priority
Jun 17, 2026
Jul 6, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which us...Show more
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.Show less
1Count
1Countly Server
Jun 17, 2026
May 17, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/username and full name specified in the databas...Show more
countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/username and full name specified in the database is capable of guessing the password reset token. The actor may use this information to reset the password and take over the account. The problem has been patched in Countly Server version 22.03.7 for servers using the new user interface and in 21.11.4 for servers using the old user interface.Show less
1Craftcms
1Craft Cms
Jun 17, 2026
May 9, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application wh...Show more
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host to the /index.php?p=admin/actions/users/send-password-reset-email URI. NOTE: the vendor's position is that a customer can already work around this by adjusting the configuration (i.e., by not using the default configuration).Show less
1Shopware
1Shopware
Jun 17, 2026
Apr 28, 2022
N/A· v4
7.5 HIGH· v3
6.8 MEDIUM· v2
Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This make...Show more
Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's account if they somehow gain access to the victims email account and find an unused password reset token in the emails. This issue is fixed in version 5.7.9.Show less
1Php
1Pearweb
Jun 17, 2026
Apr 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
1Atutor
1Atutor
Jun 17, 2026
Apr 8, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
1Automatic Question Paper Generator System Project
1Automatic Question Paper Generator System
Jun 17, 2026
Mar 29, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.
1Microweber
1Microweber
Jun 17, 2026
Mar 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
1Xwiki
1Xwiki
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is closed to guest users. This problem has been patched on XWiki 12.10.9, 13.4.1 and 13.6RC1. Users are advised yo update. There are no known workarounds for this issue.Show less
1Pega
1Infinity
Jun 17, 2026
Jan 28, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
1Saviynt
1Enterprise Identity Cloud
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local accou...Show more
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account.Show less
1Deltarm
1Delta Rm
Jun 17, 2026
Jan 18, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JS...Show more
An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).Show less
1Umbraco
1Umbraco Cms
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so th...Show more
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers server thereby disclosing the password reset token if/when the link is followed. A related vulnerability (CVE-2022-22690) could allow this flaw to become persistent so that all password reset URLs are affected persistently following a successful attack. See the AppCheck advisory for further information and associated caveats.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are acc...Show more
In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.Show less